Revolut confirms customer data breach from fake government requests

58 minutes ago 21

Revolut, the British fintech giant, just got caught by one of the oldest tricks in the cybercrime playbook: a well-crafted fake email.

The company publicly confirmed on September 12 that it had disclosed sensitive customer information after receiving fraudulent data requests sent from an email address impersonating a legitimate government agency. The spoofed messages were good enough to pass SPF, DKIM, and DMARC authentication checks, which are essentially the three-layered security system email servers use to verify that a message actually comes from who it claims to come from.

What was exposed and who was targeted

The compromised data included full names, birth dates, contact information, copies of identification documents, transaction histories, and account statements. Revolut stressed that no biometric facial telemetry data was shared during the incident. The company also maintained that no customer funds were stolen and that its core banking systems were not compromised.

Revolut has not disclosed the exact number of affected users. Reports suggest that a select group of higher-net-worth individuals may have been specifically targeted. On-chain analyst ZachXBT indicated the incident appeared to be limited in scale.

Customer notifications began circulating around September 11, one day before Revolut’s public confirmation. The company described the breach as a “sophisticated external impersonation scam.”

How email spoofing beat the safeguards

The technical detail that makes this breach particularly notable is that the fraudulent emails passed all three major email authentication protocols. SPF checks whether the sending server is authorized to send mail on behalf of a domain. DKIM verifies that the message content hasn’t been tampered with in transit. DMARC ties the two together and tells receiving servers what to do when checks fail.

Revolut’s response included blocking the fraudulent email address, contacting regulatory bodies and law enforcement, and reaching out to the government agency whose identity was impersonated. The company has not publicly named which agency was spoofed.

The bigger picture for fintech security

This is not Revolut’s first brush with a data security incident. The company experienced a breach in 2022 that affected tens of thousands of customers. That earlier incident involved unauthorized access through social engineering of an employee. This latest breach targets the compliance process itself rather than individual staff credentials.

The timing is awkward for Revolut. The company has been aggressively pursuing expansion across Europe and beyond, and has signaled ambitions toward a public listing.

For Revolut’s customers, the immediate risk is not financial but informational. The exposed data, particularly ID documents and transaction histories, is exactly the kind of material used in identity theft, targeted phishing campaigns, and social engineering attacks.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article